Executive brief
Windows Network File System (NFS) contains a buffer over-read vulnerability that allows remote attackers to crash the system and disrupt business operations. An attacker can exploit this flaw over the network without authentication to trigger a denial of service condition, impacting availability of systems relying on NFS for shared file access.
Technical details
A buffer over-read vulnerability exists in Windows Network File System that can be triggered remotely over the network. The vulnerability allows an unauthenticated attacker to read beyond allocated buffer boundaries, leading to a denial of service condition. Attack vectors do not require authentication or user interaction, making this exploitable from any network-connected system. An attacker can crash the NFS service, rendering file sharing unavailable. Patches from Microsoft are available via the Security Update Guide.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-08-11: disclosed